Microsoft
91,472 known vulnerabilities
Top Products
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A m
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A ma
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vul
VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities.
VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A m
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with a
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A m
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network a
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for
The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for p
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for
Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injec
The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its
A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerabilit
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders i
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote a
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who c
Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This
Adobe Acrobat Reader version 22.001.20085 (and earlier), 20.005.30314 (and earlier) and 17.012.30205 (and earlier) are a
Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affect
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machi
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on
A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scannin
There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local
This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can
In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.
A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects un
ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-Sh
Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite h
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started